This is a small, actively maintained PHP CS Fixer configuration package with a clear README, MIT licensing, matching repository, stable releases, and no deprecation or install-time scripts. Its main risks are the single-maintainer, single-contributor structure, minimal repository size, lack of tests and changelog, and absence of security scanning or a security policy; these reduce transparency and resilience but are less severe for a focused configuration package, especially given the 22 releases in 180 days and recent repository activity.
78%
Total Score
50
50
83
90
The package declares five runtime dependencies, including PHP CS Fixer and custom fixer packages, which is substantial for a configuration package and creates additional dependency-chain exposure. The dependencies are directly aligned with its documented purpose, so this is a caution rather than a severe concern.
Only one registry account, Gabriel Tenita, has publish access. This is a limited publishing redundancy and increases continuity risk if that account becomes inactive.
A substantive README documents installation and usage, while tests and a changelog are absent in both the artifact and repository. For a small configuration-only package, the missing tests are a moderate hygiene gap rather than a severe dependency risk.
The repository is owned by an individual user rather than an organization, so there is no organizational maintenance redundancy to offset the concentrated contributor and maintainer base.
All two recent commits came from one contributor, giving a 100% top-contributor share. With user-owned backing and no second active contributor, maintenance is concentrated and continuity risk is elevated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
the-ge/phpcsfixer-fixers Version ^1.0 | — | — |
friendsofphp/php-cs-fixer Version ^3.95 | — | — |
kubawerlos/php-cs-fixer-custom-fixers Version ^3.37 | — | — |
erickskrauch/php-cs-fixer-custom-fixers Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.